cbcvebase.
CVE-2023-53514
published 2025-10-01

CVE-2023-53514: In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix memory leak of device names The device names allocated by dev_set_name()…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.4th percentile
In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix memory leak of device names The device names allocated by dev_set_name() need be freed before module unloading, but they can not be freed because the kobject's refcount which was set in device_initialize() has not be decreased to 0. As comment of device_add() says, if it fails, use only put_device() drop the refcount, then the name will be freed in kobejct_cleanup(). device_del() and put_device() can be replaced with device_unregister(), so call it to unregister the added successfully devices, and just call put_device() to the not added device. Add a release() function to device to avoid null release() function WARNING in device_release(), it's empty, because the context devices are freed together in host1x_memory_context_list_free().

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= 8aa5bcb61612060429223d1fbb7a1c30a579fc1f < 958c6cbc32996c375af42db96ceba021a1959899958c6cbc32996c375af42db96ceba021a1959899
linuxlinux>= 8aa5bcb61612060429223d1fbb7a1c30a579fc1f < dba1aeaaf3d0e2f996cb0a5609e5e85ecf405a5cdba1aeaaf3d0e2f996cb0a5609e5e85ecf405a5c
linuxlinux>= 8aa5bcb61612060429223d1fbb7a1c30a579fc1f < 3ab0f5ddb761270b11d8c90b8550a59666cfc9bb3ab0f5ddb761270b11d8c90b8550a59666cfc9bb
linuxlinux>= 8aa5bcb61612060429223d1fbb7a1c30a579fc1f < 55879dad0f3ae8468444b42f785ad79eac05fe5b55879dad0f3ae8468444b42f785ad79eac05fe5b
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 6.0 < 6.1.286.1.28
linuxlinux_kernel>= 6.2 < 6.2.156.2.15
linuxlinux_kernel>= 6.3 < 6.3.26.3.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.